CVE Radar
Recent CVEs ranked by in-the-wild exploitation probability (EPSS + CISA KEV + CVSS). Modules below break out the most dangerous disclosures.
Last 24hby threat score
763 new- CVE-2026-80235EFenceCVSS 9.36
- CVE-2026-77533UniFi Protect ApplicationCVSS 9.96
- CVE-2026-18431Avada (Fusion) BuilderCVSS 9.86
- CVE-2026-19632TranslatePressCVSS 9.86
- CVE-2026-80138clipbucket-v5CVSS 9.26
- CVE-2026-79911N600RCVSS 9.36
- CVE-2026-80104DB-GPTCVSS 9.36
- CVE-2026-45018chainlitCVSS 9.86
- CVE-2026-76197Adobe Campaign ClassicCVSS 10.06
- CVE-2026-76195Adobe Campaign ClassicCVSS 10.06
Last 7 daysby threat score
2,791 new- CVE-2026-76904geotoolsKEVCVSS 9.890
- CVE-2026-77806SPIPKEVCVSS 9.890
- CVE-2026-69836Entra IdKEVCVSS 10.090
- CVE-2026-32475Elementor ProKEVCVSS 9.090
- CVE-2026-77136Extension "powermail"KEVCVSS 9.590
- CVE-2026-77647SPIPKEVCVSS 9.890
- CVE-2026-76071NC63CVSS 9.326
- CVE-2026-76070NC63CVSS 9.326
- CVE-2026-19874Metal Gear Online 3CVSS 9.126
- CVE-2026-56705adminerCVSS 9.325
By threat level· last 7 days
90/100
CVE-2026-76904geotoolsPoC
GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6, an SQL Injection Vulnerability is present when executing OGC Filters with PostGIS DataStore implementation: `jsonArrayContains` function; Requires PostGIS 12 or greater with a String or JSON field. For PostGIS 12 and greater `jsonArrayContains(<column>, <pointer>, <value>)` function writes `<value>` into generated SQL without escaping. Patches are
Listed in VulnCheck KEV (confirmed exploited in the wild) · CVSS base 9.8
CVSS9.8EPSS1.8%KEV
90/100
CVE-2026-77806SPIPPoC
SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to code injection via an X-Spip-Filtre HTTP request header that is mishandled by analyse_resultat_skel.
Listed in VulnCheck KEV (confirmed exploited in the wild) · CVSS base 9.8
CVSS9.8EPSS1.3%KEV
90/100
CVE-2026-69836Entra IdPoC
Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.
Listed in VulnCheck KEV (confirmed exploited in the wild) · CVSS base 10.0
CVSS10.0EPSS1.6%KEV
90/100
CVE-2026-32475Elementor ProPoC
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files.
This issue affects Elementor Pro: from n/a through 4.2.1.
Listed in VulnCheck KEV (confirmed exploited in the wild) · CVSS base 9.0
CVSS9.0EPSS0.6%KEV
90/100
CVE-2026-77136Extension "powermail"
The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly into a Fluid View as template source, without any sanitization, and renders it. An anonymous, unauthenticated user can submit Fluid template syntax in that field to execute arbitrary Fluid ViewHelpers leading to disclosure of server configuration, environment variables and application source, and potentially remote code execution. Exploitation requires only that a form field is
Listed in VulnCheck KEV (confirmed exploited in the wild) · CVSS base 9.5
CVSS9.5EPSS0.6%KEV
90/100
CVE-2026-77647SPIP
SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to incorrect identification of <?php blocks, and var_export's mishandling of certain cases such as presence of a '<' character.
Listed in VulnCheck KEV (confirmed exploited in the wild) · CVSS base 9.8
CVSS9.8EPSS2.6%KEV
26/100
CVE-2026-76071NC63PoC
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by supplying an oversized destHost parameter to the ipFilterList=mod action in netis.cgi. Attackers can exploit widthless sscanf conversions that copy user-supplied input into fixed-size stack buffers before authentication is verified, achieving remote code execution as root due to the Boa web server executing the CGI environment
EPSS 0.011 (probability of exploitation) · CVSS base 9.3 · 1 public PoC/exploit reference(s) available
CVSS9.3EPSS1.1%
26/100
CVE-2026-76070NC63PoC
Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated remote attackers to overwrite saved stack state by submitting an oversized Base64-encoded password to the login handler in /bin/netis.cgi. Attackers can exploit the custom Base64 decoder's lack of output length validation against the fixed-size stack buffer to achieve remote code execution with root privileges, as the Boa web server executes the CGI environment as root.
EPSS 0.010 (probability of exploitation) · CVSS base 9.3 · 1 public PoC/exploit reference(s) available
CVSS9.3EPSS1.0%
26/100
CVE-2026-19874Metal Gear Online 3PoC
A heap-based buffer overflow vulnerability exists in Konami's Metal Gear Online 3, originating from improper validation of lobby data fields related to kicked players. The affected function processes a list of kicked player identifiers using the lobby data key "kick_num" to determine the number of entries, and individual kicked player IDs supplied via keys in the format "kicked_id_%i". The function does not validate that "kick_num" falls within the expected bounds. The game design limits matches
EPSS 0.007 (probability of exploitation) · CVSS base 9.1 · 1 public PoC/exploit reference(s) available
CVSS9.1EPSS0.7%
25/100
CVE-2026-56705adminerPoC
Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated attackers to inject ODBC parameters via semicolons. Attackers can inject TraceFile and TraceOn parameters to write PHP code to the web root, achieving remote code execution when the trace file is accessed.
EPSS 0.005 (probability of exploitation) · CVSS base 9.3 · 2 public PoC/exploit reference(s) available
CVSS9.3EPSS0.5%
25/100
CVE-2026-71300Apache CamelPoC
Improper input validation vulnerability in Apache Camel Atmosphere Websocket component.
This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.
The camel-atmosphere-websocket producer selects which connected WebSocket peers a message is delivered to through Exchange headers, and the string values of those headers sat outside the Camel namespace: websocket.connectionKey and websocket.connectionKey.list, along with websocket.sendToAll,
EPSS 0.004 (probability of exploitation) · CVSS base 9.8 · 1 public PoC/exploit reference(s) available
CVSS9.8EPSS0.4%
25/100
CVE-2026-66906Apache CamelPoC
Relative path traversal vulnerability in Apache Camel Azure Storage Blob component.
This issue affects Apache Camel: from 4.0.0 before 4.14.9, from 4.15.0 before 4.18.4, from 4.19.0 before 4.22.0.
The camel-azure-storage-blob component can download an Azure Storage blob to the local filesystem through its downloadBlobToFile operation, writing into the directory named by the fileDir endpoint option, which is documented as usable from both the producer and the consumer. BlobOperations.downlo
EPSS 0.004 (probability of exploitation) · CVSS base 9.1 · 1 public PoC/exploit reference(s) available
CVSS9.1EPSS0.4%
25/100
CVE-2026-63039Apache InLongPoC
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to inject the string value into
the SQL statement, enabling SQL injection.
This issue affects Apache InLong: from 2.0.0 before 2.4.0.
Users are advised to upgrade to Apache InLong's 2.4.0 or cherry-pick [1] to solve it.
[1] https://github.com/apache/inlong/pull/12080 .
EPSS 0.004 (probability of exploitation) · CVSS base 9.8 · 1 public PoC/exploit reference(s) available
CVSS9.8EPSS0.4%
25/100
CVE-2026-15706Baylan Smart Meter Management Application (BMS)PoC
Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Application (BMS) allows Authentication Bypass.
This issue affects Baylan Smart Meter Management Application (BMS): before v1.1.10.142.
EPSS 0.004 (probability of exploitation) · CVSS base 9.8 · 1 public PoC/exploit reference(s) available
CVSS9.8EPSS0.4%
25/100
CVE-2026-18315TrueBookerPoC
The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key leading to Account Takeover in all versions up to, and including, 1.2.6. This is due to the admin_user_create_cus AJAX handler lacking any authentication or capability check before passing the attacker-supplied truebooker_wp_user_id parameter directly to wp_update_user. This makes it possible for unauthenticated attackers to overwrite the email address
EPSS 0.006 (probability of exploitation) · CVSS base 9.8 · 1 public PoC/exploit reference(s) available
CVSS9.8EPSS0.6%
22/100
CVE-2026-9254Archer BE800 V1PoC
An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges.
Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic.
EPSS 0.023 (probability of exploitation) · CVSS base 8.7 · 1 public PoC/exploit reference(s) available
CVSS8.7EPSS2.3%
22/100
CVE-2026-75616Archer C20 v6PoC
An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device compromise.
Successful exploitation may allow arbitrary command execution with elevated privileges, compromising the confidentiality, integrity, and availability of the affected dev
EPSS 0.019 (probability of exploitation) · CVSS base 8.5 · 1 public PoC/exploit reference(s) available
CVSS8.5EPSS1.9%
21/100
CVE-2026-16348Archer BE800 v1PoC
An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.
Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices.
EPSS 0.009 (probability of exploitation) · CVSS base 8.5 · 1 public PoC/exploit reference(s) available
CVSS8.5EPSS0.9%
21/100
CVE-2026-10053GitLabPoC
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.
EPSS 0.007 (probability of exploitation) · CVSS base 8.5 · 1 public PoC/exploit reference(s) available
CVSS8.5EPSS0.7%
20/100
CVE-2026-78122docker-socket-proxyPoC
docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. Attackers can use GET requests to /containers/{id}/archive, /containers/{id}/export, /containers/{id}/logs, and /containers/{id}/top to read arbitrary files and download entire container filesystems as tar archives.
EPSS 0.003 (probability of exploitation) · CVSS base 8.3 · 1 public PoC/exploit reference(s) available
CVSS8.3EPSS0.3%
1–20 of 2,791
Page/ 140